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1 . A method tfbr sharing a security context between different sessions 
on a database server, comprising: 

receiving a request kt the database server through a database session 
between the database servenand an application on a database client; 

looking up an identifier for an application client that identifies a client of 
the application, the identifier \iaving been previously associated with the database 
session; 

using the identifier to lAok up the security context for the application client 
within a storage area associated with the database server; 

wherein the security context includes attributes related to the application 
client; and 

performing a database operation to satisfy the request; 
wherein performing the database operation involves enforcing access 
rights associated with the security (context. 



1 2. The method of claiiji 1 ? wherein the request includes a database 

2 query directed to a database on the database server. 
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3. The method of claink 2, wherein performing the database operation 
involves modifying the database qujery to enforce access rights associated with the 
security context. 
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4. The method of claim \l , wherein the identifier for the application 
client identifies a user of the application that is sending the request to the database 



server. 
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5. The method of claim 1 , 

wherein the database client is an application server that is sending the 
request to the database server; and 

wherein the identifier for the application client identifies an application 
session between the application on the application server and the client of the 



application. 

6. The methoc 
receiving a request 
associated with the database 

changing the application 



of claim 5, further comprising: 
from the application to change the application session 
session; and 

session associated with the database session. 



The method 



0 



pooling by periodically chaq; 
database session in order to 
sessions through the databas 



f claim 5, further comprising facilitating connection 
ging the application session associated with the 
channel requests associated with multiple application 
session. 



8. The method 
method further comprises: 

receiving the security 
client; and 

inserting the security 
database server so that the 
application client. 



f claim 1, wherein prior to receiving the request the 

context for the application client from the database 

context into the storage area associated with the 
security context can be indexed by the identifier for the 
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9. The method of claim 1, further comprising allowing the application 
client to use the same security context through a second application and a second 
database session by: 

receiving a secoiid request at the database server through the second 
database session with the second application; 

looking up the identifier for the application client, the identifier having 
been previously associated with the second database session; and 

using the identifier \to look up the security context for the application client 
within the storage area associated with the database server. 
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10. A computer-ijpadable storage medium storing instructions that 
when executed by a computet cause the computer to perform a method for sharing 
a security context between different sessions on a database server, the method 
comprising: 

receiving a request at the database server through a database session 
between the database server and an application on a database client; 

looking up an identifierlfor an application client that identifies a client of 
the application, the identifier halving been previously associated with the database 
session; 

using the identifier to look up the security context for the application client 
within a storage area associated with the database server; 

wherein the security context includes attributes related to the application 
client; and 

performing a database operation to satisfy the request; 
wherein performing the database operation involves enforcing access 
rights associated with the securiW context. 
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1 1 . The compuier 
request includes a database 



12. The comput 
performing the database operation 
enforce access rights associated 



identifier for the application 
sending the request to the d 



-readable storage medium of claim 10, wherein the 
query directed to a database on the database server. 



er-readable storage medium of claim 1 1, wherein 
involves modifying the database query to 
with the security context. 



1 3 . The compute r-readable storage medium of claim 1 0, wherein the 



client identifies a user of the application that is 
akabase server. 



14. The computerireadable storage medium of claim 10, 
wherein the database dlient is an application server that is sending the 

request to the database server;! and 

wherein the identifier lor the application client identifies an application 
session between the applicatio|i on the application server and the client of the 
application. 

15. The computer-readable storage medium of claim 14, wherein the 
method further comprises: 

receiving a request from the application to change the application session 
associated with the database session; and 

changing the application session associated with the database session. 

16. The computer-readable storage medium of claim 14, wherein the 



method further comprises facili 



ating connection pooling by periodically changing 



the application session associated with the database session in order to channel 
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1 requests associated wit^ multiple application sessions through the database 

2 session. 



1 7. The computer-readable storage medium of claim 1 0, wherein prior 
to receiving the request the method further comprises: 

receiving the security context for the application client from the database 
client; and 

inserting the seciirity context into the storage area associated with the 
database server so that tlje security context can be indexed by the identifier for the 
application client. 

18. The computer-readable storage medium of claim 1 0 ? wherein the 
method allows the application client to use the same security context through a 

xond database session by: 
request at the database server through the second 
database session with the s ttond application; 

looking up the iden ifier for the application client, the identifier having 
with the second database session; and 
tp look up the security context for the application client 
iated with the database server. 



second application and a s 
receiving a second 



been previously associated 
using the identifier 
within the storage area asso< 



19. An apparatus that facilitates sharing a security context between 
different sessions on a database server, comprising: 

a receiving mechanism that is configured to receive a request at the 
database server through a dstabase session between the database server and an 
application on a database client; 
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a lookup mecharlism that is configured to look up an identifier for an 
application client that identifies a client of the application, the identifier having 
been previously associat ed with the database session; 

wherein the look jp mechanism is configured to use the identifier to look 
up the security context for the application client within a storage area associated 
with the database server; 

wherein the secuilit 
client; and 

that is configured to perform a database operation to 



ty context includes attributes related to the application 



a database engine 
satisfy the request; 

wherein performing the database operation involves enforcing access 
rights associated with the security context 



1 20. The 

2 query directed to a databasfe 



apparatus of claim 19, wherein the request includes a database 
on the database server. 



21. The apparatus 
configured to perform the database 
enforce access rights associited 



22. The apparatu 
application client identifies 
the database server. 

23. The apparatu: 
wherein the database 



of claim 19, wherein the database engine is 

operation by modifying the database query to 
with the security context. 



of claim 19, wherein the identifier for the 

user of the application that is sending the request to 



of claim 19, 

client is an application server that is sending the 



request to the database server and 
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wherein the identifier for the application client identifies an application 
session between the application on the application server and the client of the 
application. 
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24. The appjaratus of claim 23, wherein the receiving mechanism is 
additionally configured! to receive a request from the application to change the 
application session associated with the database session; and 

further comprising a changing mechanism that is configured to change the 
application session associated with the database session in response to the request. 
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25. The apparatus of claim 24, wherein the changing mechanism is 
further configured to facilitate connection pooling by periodically changing the 
application session associated with the database session in order to channel 
requests associated with multiple application sessions through the database 
session. 



of claim 19, wherein the receiving mechanism is 
the security context for the application client from 



1 26. The apparati 

2 further configured to receive 

3 the database client; and 

4 further comprising a Security context initialization mechanism that is 

5 configured to insert the secuiity context into the storage area associated with the 

6 database server so that the sejcurity context can be indexed by the identifier for the 

7 application client. 



27. The apparatus 



of claim 1 9, 
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1 wherein the receiving mechanism is further configured to receive a second 

2 request at the database se:rver through a second database session between the 

3 database server and a second application; and 

4 wherein the lookup mechanism is further configured to look up the 

5 identifier for the application client, the identifier having been previously 

6 associated with the second database session; and 

7 wherein the lookup mechanism is further configured to use the identifier to 

8 look up the security contdbct for the application client within the storage area 

9 associated with the database server. 
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